Senior Penetration Tester (iGaming)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Penetration Tester (iGaming): Strengthening high-load iGaming products through offensive security assessments across applications, infrastructure, cloud environments, mobile platforms, and payment flows with an accent on AWS, Kubernetes, APIs, and business-critical workflows. Focus on red-team and assumed-breach exercises, identifying complex vulnerabilities, and translating findings into practical remediation with engineering, product, fraud, and compliance stakeholders.
Location: Remote from Poland or Serbia
Company
operates in the iGaming sector, developing and supporting high-load digital products and payment-related workflows.
What you will do
- Plan and execute penetration tests across web applications, APIs, mobile applications, internal and external infrastructure, and AWS environments.
- Conduct red-team and assumed-breach exercises covering privilege escalation, lateral movement, persistence, and data exfiltration.
- Assess Kubernetes, cloud-native services, microservices, CI/CD pipelines, and Infrastructure as Code implementations.
- Test payment systems, wallets, KYC/AML processes, bonus mechanisms, affiliate tracking, and other business-critical workflows.
- Collaborate with Product, Engineering, AppSec, Payments, Fraud, and compliance stakeholders to prioritize findings and support remediation.
- Develop testing scripts and tools, contribute to threat modeling, review reports, and guide junior and middle security specialists.
Requirements
- 4+ years of hands-on penetration testing or offensive security experience.
- Practical experience in at least three areas including web applications and APIs, internal networks, external infrastructure, cloud environments, or mobile applications.
- OSCP or an equivalent offensive security certification.
- Strong knowledge of SAST, SCA, DAST, AWS or GCP, MITRE ATT&CK, OWASP ASVS, OWASP WSTG, and PTES.
- Experience with Python or Bash, IAM models, Kubernetes, CI/CD pipelines, and Infrastructure as Code tools such as GitLab, GitHub Actions, Jenkins, Terraform, Helm, or CloudFormation.
- Upper-Intermediate English or higher, strong reporting and communication skills, and knowledge of PCI DSS, ISO 27001, NIST, and GDPR.
Nice to have
- Advanced offensive security certifications such as OSWE, OSEP, OSED, CRTO, BSCP, ARTE, or GRTE.
- Experience designing secure Kubernetes and AWS architectures.
- Background in iGaming, fintech, or payment products.
- Public security research, CVEs, advisories, technical publications, conference presentations, HTB Pro Labs, or strong CTF achievements.
- Contributions to open-source offensive or defensive security projects.
Culture & Benefits
- Generous annual leave and paid sick leave.
- Private medical and dental insurance, sports allowance, and food vouchers.
- Education budget and professional development opportunities.
- Modern office with complimentary meals, snacks, and wellness initiatives.
- Recognition programs, regular team events, and gifts for personal milestones.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →